Skip to content
Back to skills

Skillguard

ASecurity

Security scanner for AgentSkill packages. Scan skills for credential theft, code injection, prompt manipulation, data exfiltration, and evasion techniques before installing them. Use when evaluating skills from ClawHub or any untrusted source.

  • 651 stars
  • 0 votes
  • 0 copies
  • 6 views
  • Added February 10, 2026
toolsrustbashnodesecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned February 12, 2026

npx -y skills add sundial-org/awesome-openclaw-skills --skill skillguard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skillguard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Skillguard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/sundial-org-skillguard/badge)](https://www.skillsdirectory.com/skills/sundial-org-skillguard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: skillguard
description: Security scanner for AgentSkill packages. Scan skills for credential theft, code injection, prompt manipulation, data exfiltration, and evasion techniques before installing them. Use when evaluating skills from ClawHub or any untrusted source.
metadata: {"openclaw": {"requires": {"bins": ["node"]}}}
---

# SkillGuard — Agent Security Scanner

When asked to check, audit, or scan a skill for security, use SkillGuard.

## Commands

### Scan a local skill directory
```bash
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan <path>
```

### Scan with compact output (for chat)
```bash
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan <path> --compact
```

### Check text for prompt injection
```bash
node /home/claw/.openclaw/workspace/skillguard/src/cli.js check "<text>"
```

### Batch scan multiple skills
```bash
node /home/claw/.openclaw/workspace/skillguard/src/cli.js batch <directory>
```

### Scan a ClawHub skill by slug
```bash
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan-hub <slug>
```

## Score Interpretation
- 80-100 ✅ LOW risk — safe to install
- 50-79 ⚠️ MEDIUM — review findings before installing
- 20-49 🟠 HIGH — significant security concerns
- 0-19 🔴 CRITICAL — do NOT install without manual review

## Output Formats
- Default: full text report
- `--compact`: chat-friendly summary
- `--json`: machine-readable full report
- `--quiet`: score and verdict only

Files in this skill

  • README.md7.1 KB
  • RED-TEAM-NOTES.md4.8 KB
  • SKILL.md1.4 KB
  • package.json411 B
  • rules/dangerous-patterns.json5.9 KB
  • src/ast-analyzer.js22.2 KB
  • src/clawhub.js1.9 KB
  • src/cli.js5.2 KB
  • src/index.js1.7 KB
  • src/prompt-analyzer.js20.8 KB
  • src/reporter.js6.5 KB
  • src/scanner.js31 KB
  • test-fixtures/clean-skill/SKILL.md332 B
  • test-fixtures/clean-skill/weather.js501 B
  • test-fixtures/evasive-01-string-concat/SKILL.md152 B
  • test-fixtures/evasive-01-string-concat/index.js693 B
  • test-fixtures/evasive-02-encoded/SKILL.md117 B
  • test-fixtures/evasive-02-encoded/index.js829 B
  • test-fixtures/evasive-03-prompt-subtle/SKILL.md1.2 KB
  • test-fixtures/evasive-04-timebomb/SKILL.md130 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…